Agent skill

Security Audit

by Aedelon in Aedelon/claude-code-blueprint

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

Custom licenceAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add Aedelon/claude-code-blueprint --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Aedelon/claude-code-blueprint security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Aedelon/claude-code-blueprint.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
120
Token cost
~1.6k tokens
SKILL.md length
347 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
Custom licence

At a glance

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

  • Works in 4 steps: Automated Scans → Manual Review → Classify Findings → …
  • Mentions: security
  • SKILL.md covers Overview, Process, Phase 1: Automated Scans and Phase 2: Manual Review, plus 3 more sections
  • Calls npm, uv and cargo

What it does

Security Audit is an agent skill from Aedelon/claude-code-blueprint. Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. MUST BE USED when user mentions: "security", "vulnerability", "audit", "OWASP", "CVE", "security review", "pentest", "injection", "XSS", "CSRF", "authentication", "authorization", "secrets", "hardcoded password", "secure", "npm audit", "pip-audit", "check security", "is this secure", "security risk", "data leak", "SQL injection", "command injection", "path traversal"…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Security review and Vulnerability scanning. It works with Semgrep, Snyk, Trivy and SQL. The repository describes itself as: Production-grade Claude Code configuration: skills, agents, hooks, rules, and permissions working as a system.

When your agent uses it

  • Mentions: security
  • Security review
  • Hardcoded password
  • Command injection

Example prompts

  • “security”
  • “vulnerability”
  • “security review”
  • “/security-audit”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, WebSearch, WebFetch, Agent

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Automated Scans
  2. Manual Review
  3. Classify Findings
  4. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 3bb5099. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • WebSearch
    • WebFetch
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • uv
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.6k tokens when it runs. Until then it costs about 205 tokens; SKILL.md has 347 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~205
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:66
    - .env files: verify .env is listed in .gitignore
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, WebSearch, WebFetch, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 347 words (~1,587 tokens).

“Systematic security review covering OWASP Top 10, dependency vulnerabilities, secrets, and secure patterns.”

— opening of SKILL.md by Aedelon, Custom licence
name
security-audit
allowed-tools
Read, Grep, Glob, Bash, WebSearch, WebFetch, Agent

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/security-audit of Aedelon/claude-code-blueprint.

Open the folder on GitHubat commit 3bb5099

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillAedelon/claude-code-blueprint120—~1.6kAutomated safety check: NotesCustom licence
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Security Auditstaruhub/ClaudeSkills727—~1.3kAutomated safety check: NotesMIT
Security Scanericrisco/rsc-harness167—~2.8kAutomated safety check: NotesMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Audit

    staruhub/ClaudeSkills

    全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

    727 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    167 GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from Aedelon/claude-code-blueprint

All 8 skills in this repo
  • Anti Hallucination

    Aedelon/claude-code-blueprint

    CRITICAL SAFETY SKILL — Verify ALL technical claims, API signatures, library methods, code behavior, and factual statements before answering.

    120 GitHub stars~1.1k tokensUpdated 7 mo ago
    Auto-check passed
  • Brainstorm

    Aedelon/claude-code-blueprint

    Multi-agent brainstorming and strategic thinking on any complex topic.

    120 GitHub stars~1.1k tokensUpdated 7 mo ago
    Auto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    Auto-check passed
  • Commit Message

    Aedelon/claude-code-blueprint

    Ship workflow: review changes, generate conventional commit messages, push, and create PRs.

    120 GitHub stars~1.4k tokensUpdated 7 mo ago
    Auto-check: notes
  • Core Protocols

    Aedelon/claude-code-blueprint

    Debug errors systematically by searching first, then analyzing, then proposing verified solutions.

    120 GitHub stars~997 tokensUpdated 7 mo ago
    Auto-check passed
  • Research Protocol

    Aedelon/claude-code-blueprint

    Conduct rigorous research with proper citations (DOI, arXiv, PMID) and source triangulation.

    120 GitHub stars~1.1k tokensUpdated 7 mo ago
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. Security Audit is an agent skill from Aedelon/claude-code-blueprint. Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

When should I use Security Audit?

Security Audit fits situations like: mentions: security; security review; hardcoded password; command injection.

How do I install Security Audit in Claude Code?

Run `npx skills add Aedelon/claude-code-blueprint --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in Aedelon/claude-code-blueprint) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add Aedelon/claude-code-blueprint --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in Aedelon/claude-code-blueprint) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Aedelon/claude-code-blueprint --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (npm, uv and cargo). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebSearch, WebFetch, Agent.

Does Security Audit access the network?

SKILL.md contains no URLs. Its commands use npm and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Security Audit use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Security Reviewer (Jeffallan/claude-skills, 12k stars), Security Audit (staruhub/ClaudeSkills, 727 stars), Security Scan (ericrisco/rsc-harness, 167 stars) and Security Auditor (eigent-ai/eigent, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

Aedelon (a GitHub user) maintains it in Aedelon/claude-code-blueprint, which has 120 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on March 4, 2026.

Source: Aedelon/claude-code-blueprint on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.